Skip to content
186 linesCodeBlameRaw
1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-billing",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
6 // Runs next to its database: a request makes several queries in turn,
7 // and each would otherwise cross the distance to it.
8 "placement": { "mode": "off" },
9 "main": "build/index.js",
10 "build": { "command": "node ../../scripts/build-rust-worker.mjs" },
11 // Reached only through service bindings.
12 "workers_dev": false,
13 "d1_databases": [
14 {
15 "binding": "DB",
16 "database_name": "g1t-billing",
17 "database_id": "695a6979-fd07-4850-bc97-904a6b4b7a04",
18 "migrations_dir": "migrations"
19 }
20 ],
21 // Identity emails owners as their workspace nears its usage limit.
22 // Repos says which repositories are public (the open-source pool pays
23 // for work on those) and what private ones hold (the storage meter).
24 "services": [
25 { "binding": "IDENTITY", "service": "g1t-identity" },
26 { "binding": "REPOS", "service": "g1t-repos" },
27 // What each workspace's packages hold, measured daily (src/storage.rs).
28 { "binding": "PACKAGES", "service": "g1t-packages" }
29 ],
30 // Margin alerts to staff (src/margin.rs), through Cloudflare Email
31 // Sending like identity's and the status page's mail.
32 "send_email": [{ "name": "EMAIL", "remote": true }],
33 // Events from the bus: a workspace renamed moves its billing to the
34 // new slug (src/rename.rs).
35 "queues": {
36 "consumers": [{ "queue": "g1t-events-billing", "max_batch_size": 20, "max_batch_timeout": 1, "max_retries": 3, "dead_letter_queue": "g1t-events-dlq" }]
37 },
38 "vars": {
39 // What is added to a model run's cost, in percent: g1t's overhead for
40 // running and building it. The price book's markups are the same.
41 "MARGIN_PERCENT": "20",
42 // While g1t is being built out, workspaces pay nothing: runs are
43 // recorded with what they cost, and nothing is charged. Set to
44 // "false" when pricing starts.
45 // Off: workspaces are charged as their account's terms say. g1t's own
46 // (flagon-io, Flagon, Inc.'s) is comped in sudo.g1t.sh, not by this switch.
47 "FREE_WHILE_BUILDING": "false",
48 // The g1t plan (src/features.rs): $20 a month per workspace, never
49 // per person. It includes $10 of usage a month at cost plus 20%, used
50 // first and not rolled over; the other $10 pays for running g1t, the
51 // free forge for everyone, and the people building it. No quotas:
52 // builds, requests, CPU, custom domains, storage and git operations
53 // are all metered at cost plus 20% and drawn from the $10 first; only
54 // the workspace's spend limit stops it. Projects are not metered.
55 "PLAN_MONTHLY_CENTS": "2000",
56 "PLAN_INCLUDED_MICROS": "10000000",
57 // 1 GB of private storage free for every workspace: past it, the plan
58 // pays at cost plus the margin, and a free workspace's pushes to
59 // private repositories stop.
60 "FREE_PRIVATE_STORAGE_BYTES": "1000000000",
61 // What public and private packages may hold for free; past them a free
62 // workspace's pushes are refused, and the plan pays at cost plus the margin.
63 "PUBLIC_PACKAGES_FREE_BYTES": "10000000000",
64 "PRIVATE_PACKAGES_FREE_BYTES": "500000000",
65 // The audit log (src/retention.rs): 7 days for a free workspace, 90 on
66 // the plan, for g1t's own and for an enterprise. Staff can set an
67 // account's own days in sudo, up to AUDIT_MAX_DAYS; keep that at most
68 // the events service's AUDIT_MAX_DAYS, which deletes anything older.
69 "FREE_AUDIT_RETENTION_DAYS": "7",
70 "AUDIT_RETENTION_DAYS": "90",
71 "AUDIT_MAX_DAYS": "400",
72 // The trial (src/credits.rs, src/cards.rs): $5 of usage once per new
73 // workspace, granted after a card check (one per card), out of a pool
74 // for everyone ($100) that resets each calendar month (UTC). Either at
75 // 0 turns new trials off. Never for deployments.
76 "TRIAL_WORKSPACE_MICROS": "5000000",
77 "TRIAL_MONTHLY_POOL_MICROS": "100000000",
78 // g1t's open-source pool: checks, workflows and the merge queue on
79 // public repositories, for any workspace with a card check, up to $25
80 // a month in all and $2 a month for any one repository.
81 "OSS_POOL_MICROS": "25000000",
82 "OSS_REPO_MICROS": "2000000",
83 // Ceilings on usage not yet paid for (src/limits.rs): $3 for a free
84 // workspace (it has no on-demand compute), $100 for a paid one's first
85 // month, then twice what it has paid as payments clear, between the
86 // start and $1,000 (Established: its monthly spend, up to $10,000).
87 "LIMIT_NEW_MICROS": "3000000",
88 "LIMIT_PAID_START_MICROS": "100000000",
89 "LIMIT_PAID_MIN_MICROS": "25000000",
90 "LIMIT_PAID_MAX_MICROS": "1000000000",
91 // Caps on agents (src/compute.rs): what the agents on one issue may
92 // spend in all. One run's spend cap is DEFAULT_RUN_CAP_MICROS in
93 // crates/contracts (guardrails.rs), shared with the guardrails' cost
94 // per run; RUN_CAP_MICROS here would override it. Owners and staff
95 // can change both.
96 "ISSUE_CAP_MICROS": "10000000",
97 // A spike: an hour's spend above 5 times the usual hour over the last
98 // week, and at least $5, pauses new compute until an owner confirms.
99 "SPIKE_FACTOR": "5",
100 "SPIKE_FLOOR_MICROS": "5000000",
101 // The most of an overage's real cost a one-click goodwill credit
102 // covers (src/overages.rs); it always gives back the margin too.
103 "OVERAGE_FORGIVE_COST_MICROS": "50000000",
104 // Git operations through g1t (src/storage.rs): 50,000 a month free for
105 // every workspace; past it the plan pays at cost plus 20% and is never
106 // slowed, and a free workspace is slowed down by the repos service
107 // (its GIT_OPERATIONS_FREE_CAP, the same number), never charged.
108 "GIT_OPERATIONS_INCLUDED": "50000",
109 // A month's close charges no less than $5, so a payment's fee is never
110 // most of it: smaller amounts carry over. Charges at a limit always go
111 // through.
112 "MIN_CHARGE_MICROS": "5000000",
113 // Where the keeper reads what g1t pays (src/keeper.rs). Its token,
114 // CLOUDFLARE_USAGE_TOKEN, is a secret: Billing, Account Analytics
115 // and AI Gateway, read only. The daily cost reconciliation
116 // (src/costs.rs, src/margin.rs) reads the bill with
117 // CLOUDFLARE_BILLING_TOKEN (Account: Billing Read, Account Analytics
118 // Read) when it is set, else with the usage token. With neither it
119 // reconciles only what g1t counted itself. See
120 // docs/BILLING_OPERATIONS.md.
121 "CLOUDFLARE_ACCOUNT_ID": "1e6f2cffa3f445920836e8ebe446bb58",
122 // The day of the month the account's billing cycle starts on (Sep 28
123 // to Oct 27): the usage bill's included amounts are a cycle's
124 // (src/cycle.rs). The subscriptions' read (current_period_start)
125 // takes over once it has worked.
126 "CLOUDFLARE_BILLING_DAY": "28",
127 "AI_GATEWAY_ID": "g1t",
128 // Where margin alerts go: a product or all of g1t under the margin
129 // floor, leaks, drift. Empty sends none (sudo still shows them).
130 "COSTS_ALERT_EMAIL": "hey@flagon.io",
131 // What g1t pays for itself, capped (src/budget.rs), at cost:
132 // a comped account's (flagon-io's) work, $150 a month, unless its
133 // terms in sudo set its own limit; alerts at 50, 75, 90 and 100% to
134 // COSTS_ALERT_EMAIL, and at 100% new work on it is refused.
135 "COMPED_MONTHLY_CEILING_MICROS": "150000000",
136 // All of g1t's own spend in a day (comped, the trial and open-source
137 // pools, free overruns, anything charged without real money): at
138 // $75, new agent runs on hosted models that g1t pays for pause until
139 // 00:00 UTC; staff are emailed and can lift it in sudo. Workspaces
140 // paying with real money are never paused. 0 turns either cap off.
141 "PLATFORM_DAILY_SPEND_CAP_MICROS": "75000000",
142 // The platform watch (src/platform.rs, docs/SPEND-GUARDRAILS.md): at
143 // a quarter past each hour, what Cloudflare counted in the hour
144 // before, per metric, against these thresholds. Each is a dollar or
145 // a few an hour at list prices, far above a small alpha's hour; 0
146 // turns that metric's threshold off. Over one, staff are emailed
147 // (COSTS_ALERT_EMAIL, once per metric every 6 hours) and sudo shows
148 // it.
149 "PLATFORM_HOURLY_WORKERS_REQUESTS": "20000000",
150 "PLATFORM_HOURLY_WORKERS_CPU_MS": "100000000",
151 "PLATFORM_HOURLY_D1_ROWS_READ": "2000000000",
152 "PLATFORM_HOURLY_D1_ROWS_WRITTEN": "5000000",
153 "PLATFORM_HOURLY_QUEUE_OPERATIONS": "5000000",
154 "PLATFORM_HOURLY_DO_REQUESTS": "20000000",
155 "PLATFORM_HOURLY_DO_ROWS_WRITTEN": "5000000",
156 "PLATFORM_HOURLY_DO_STORAGE_WRITE_UNITS": "5000000",
157 "PLATFORM_HOURLY_DO_ACTIVE_SECONDS": "3000000",
158 "PLATFORM_HOURLY_KV_READS": "10000000",
159 "PLATFORM_HOURLY_KV_WRITES": "200000",
160 "PLATFORM_HOURLY_KV_DELETES": "200000",
161 "PLATFORM_HOURLY_KV_LISTS": "200000",
162 "PLATFORM_HOURLY_ARTIFACTS_EVENTS": "1000000",
163 // A spike: an hour over 10 times the last week's median hour, and at
164 // least 10% of its threshold. Emailed, never paused by itself.
165 "PLATFORM_SPIKE_FACTOR": "10",
166 "PLATFORM_SPIKE_FLOOR_PERCENT": "10",
167 // Severe: 5 times a threshold pauses the levels that metric feeds,
168 // of those AUTO_PAUSE names (compute, schedules, indexing, renders;
169 // comma-separated, empty for none). Staff resume them in sudo.
170 "PLATFORM_SEVERE_FACTOR": "5",
171 "AUTO_PAUSE": "schedules,indexing",
172 // Cloudflare's fixed subscriptions a month, for sudo's figures only:
173 // Workers Paid ($5) and Workers for Platforms ($25).
174 "CLOUDFLARE_FIXED_MONTHLY_MICROS": "30000000"
175 },
176 // Settling runs every 15 minutes, and the tick at a quarter past each
177 // hour also runs the platform watch; checking costs daily (keeper::DAILY).
178 "triggers": { "crons": ["*/15 * * * *", "17 4 * * *"] },
179 // Secrets: STRIPE_SECRET_KEY. Without it nothing is charged and the
180 // runner decides who may start agents some other way.
181 // STRIPE_WEBHOOK_SECRET: the signing secret (whsec_…) of the destination
182 // made in Stripe's dashboard for https://api.g1t.sh/stripe/webhook.
183 // Without it every event is refused (the replay still reads them).
184 // Every log kept: money moves here, and every failure matters.
185 "observability": { "enabled": true, "head_sampling_rate": 1 }
186}